CVE-2022-39193

An issue was discovered in the CheckUser extension for MediaWiki through 1.39.x. Various components of this extension can expose information on the performer of edits and logged actions. This information should not allow public viewing: it is supposed to be viewable only by users with checkuser access.
References
Link Resource
https://phabricator.wikimedia.org/T311337 Exploit Issue Tracking
Configurations

Configuration 1

cpe:2.3:a:mediawiki:mediawiki:1.39.0:rc0:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.39.0:rc1:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.39.0:-:*:*:*:*:*:*
cpe:2.3:a:mediawiki:mediawiki:1.39.1:*:*:*:*:*:*:*

Information

Published : 2023-01-20 07:15

Updated : 2023-02-02 04:55


NVD link : CVE-2022-39193

Mitre link : CVE-2022-39193

Products Affected
No products.
CWE